conference-paper
Analyzing Attacks on Client-Side Honeypots from Representative Malicious Web Sites
Research footprint
At a glance
- Citations
- 1
- References
- 12
- Comments
- 0
Paper overview
Abstract
Client-side cyberattacks are becoming more common relative to server-side cyberattacks. This work tested the ability of the honeyclient software Thug to detect malicious or compromised servers that secretly download malicious files to clients, and tested its ability to classify these exploits. We tested Thug's analysis of delivered exploits in different configurations. Results on randomly generated Internet addresses found a low rate of maliciousness of 5.6%, and results on a blacklist of 83,667 suspicious Web sites found 163 unique malware files. Thug demonstrates the usefulness of client-side honeypots in analyzing harmful data presented by malicious Web sites.
Record transparency
Publication details
- DOI
- 10.1109/csci58124.2022.00162
- OpenAlex
- W4386160548
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.